skills/joker-ye/skills/skill-creator/Gen Agent Trust Hub

skill-creator

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Python's subprocess module to execute the claude CLI and local evaluation scripts. This is a core functional requirement for verifying how other skills are triggered and performed.
  • [EXTERNAL_DOWNLOADS]: The eval-viewer/viewer.html file references external assets including Google Fonts and the SheetJS library (cdn.sheetjs.com) for rendering spreadsheets in the report. These are well-known services used for UI presentation.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted user prompts and subagent outputs during the skill improvement loop. It uses structured XML-like delimiters (e.g., <skill_content>, <attempt>) to separate instructions from data during the description optimization process.
  • Ingestion points: evals/evals.json, feedback.json, and subagent transcripts.
  • Boundary markers: Employs explicit XML-style tags and imperative instructions to Claude to focus on intent generalization.
  • Capability inventory: Includes file system access (read/write), subprocess execution, and local HTTP server hosting.
  • Sanitization: Employs HTML escaping in report generation and validates SKILL.md frontmatter formatting.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 10:44 AM
Security Audit — agent-trust-hub — skill-creator